The generated proofs are proofs by sequences
of games, as used by cryptographers. These proofs are valid for
a number of sessions polynomial in the security parameter, in the
presence of an active adversary. CryptoVerif can also evaluate
the probability of success of an attack against the protocol
as a function of the probability of breaking each cryptographic
primitive and of the number of sessions (exact security).

This prover is available below.
This software is under development; please use it at your own risk.
Comments and bug reports welcome.